VALLEYWISE HEALTH EHR ACCESS AGREEMENT.PDF

Maricopa County — Formal (2022-06-08)

View PDF Item 86 Meeting page

Extracted text (via pymupdf) 30573 characters
1 
 
AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION 
IN THE  
VALEYWISE HEALTH ELECTRONIC HEALTH RECORDS SYSTEM 
 
 
THIS AGREEMENT for Access to Valleywise Health Valleywise Health’s Protected Health Information (“PHI”) 
(“Agreement”) is entered into effective as of the 18th day of May, 2022 (“Effective Date”) between Maricopa County 
Special Health Care District d.b.a. Valleywise Health (hereinafter “Valleywise Health”) and the Maricopa County by 
and through its Department of Public Health (MCDPH), Office of Epidemiology (“External Entity”) and 
(collectively referred to as “Parties”). 
 
WHEREAS, Valleywise Health utilizes certain systems which allow authorized users to remotely access Valleywise 
Health patient electronic health records (“Valleywise Health EHR System”) that are maintained by and within 
Valleywise Health, including those providers who are members of Valleywise Health’ Medical Staff and such other 
health care providers contractually affiliated with Valleywise Health.  
 
WHEREAS, the Valleywise Health EHR System has the capacity to allow these parties to view Valleywise Health’ 
electronic health records (“EHR”) of Valleywise Health patients for the purpose of treatment, payment, and certain health 
care operations to the extent permitted without authorization by the Administrative Simplification subtitle of the Health 
Insurance Portability and Accountability Act of 1996, and the rules and regulations promulgated thereunder, as may be 
amended from time to time (collectively, “HIPAA”), and further subject to the American Recovery and Reinvestment 
Act of 2009 (“ARRA”), including its provisions Health Information Technology for Economic and Clinical Health Act 
( “HITECH Act,”) and rules and regulations promulgated thereunder, as may be amended from time to time; and, 
 
WHEREAS, Valleywise Health believes that the use of the Valleywise Health EHR System by External Entity would 
facilitate the treatment, payment, and certain health care operations for health care provided to Valleywise Health 
patients, and therefore wishes to allow External Entity to access EHR via the Valleywise Health EHR System subject to 
the restrictions and other requirements set forth in this Agreement; and, 
 
WHEREAS, External Entity provides professional and other medical services to Valleywise Health patients, but does 
not otherwise have a contract with Valleywise Health for access to the Valleywise Health EHR System; and, 
 
WHEREAS, External Entity has agreed to use the Valleywise Health EHR System to improve the quality and efficiency 
of medical services External Entity provides to Valleywise Health patients, subject to the terms herein; and  
 
NOW, THEREFORE, in consideration of the promises, the mutual agreements and covenants herein contained, and 
other good and valuable consideration, the Parties agree as follows: 
 
1. Definitions. 
 
Authorized User: External Entity and its Authorized User are External Entity’s employed or contracted physician, nurse, 
or other specifically identified and authorized person under this Agreement to use the Valleywise Health EHR System 
to access Valleywise Health patient Electronic Health Records for a Permitted Use.  Authorized Users are identified in 
Exhibit A, attached hereto.   
 
External Entity Administrator: External Entity shall also designate a liaison (“External Entity Administrator”) to 
coordinate user access. The External Entity Administrator is responsible for managing the modification and termination 
of accounts that the External Entity is granted. 
 
Permitted Use:  External Entity’s Permitted Use under this Agreement is limited to “Read Only Access” to the 
Valleywise Health EHR System for the purpose of treatment, payment or certain health care operations.  Notwithstanding

2 
 
the foregoing, Permitted Use does not include selling or otherwise making commercial use of a EHR without the 
Individual’s prior written consent as set forth in A.R.S. § 36-3805(B) or transferring data or de-identified health 
information for the purpose of clinical research or as part of a set of data for an application for grant or other clinical 
research funding with the Individual’s consent for the transfer as provided in A.R.S. § 36-3805(C).   
 
2. Valleywise Health EHR System Access. 
 
2.1 
Subject to the terms and conditions of this Agreement, Valleywise Health hereby grants External Entity non-
transferable, non-delegable, and non-exclusive access to the Valleywise Health EHR System to permit Authorized Users 
who require access to patient Electronic Health Records, as defined and set forth in Exhibit A attached hereto, to 
electronically access and use the Valleywise Health EHR System solely to facilitate External Entity’s access to EHR for 
a Permitted Use (the “System License”).  
 
2.2 
External Entity will identify and authenticate its Authorized Users, with the role of each Authorized User noted, 
on Exhibit A.  External Entity will ensure that each Authorized User participates in training on the requirements of this 
Agreement. Authorized Users shall also complete Valleywise Health training on the use of Valleywise Health EHR as 
required by Valleywise Health prior to the logon credentials being provided. Authorized Users will include only External 
Entity’s staff members with whom External Entity has an employment or a contractual relationship and will be limited 
to those who require access to the Valleywise Health EHR System to facilitate External Entity’s access for a Permitted 
Use. 
 
2.3 
External Entity shall provide Valleywise Health with information for its Privacy Officer on Exhibit A and shall 
properly notify Valleywise Health of any change to such contact.  
 
2.4 
External Entity Administrator may add Authorized Users with seven (7) day’s prior written notice to 
Valleywise Health. External Entity Administrator must remove persons no longer Authorized Users by notifying the 
Valleywise Health- Health Information Management Department not later than twenty-four (24) hours of change in 
status by calling (602)344-5266. Furthermore, External Entity agrees to notify Valleywise Health in writing when 
practicable but not later than twenty-four (24) hours after separation, when any Authorized User is separated from 
employment or is no longer an agent of External Entity for any reason, including but not limited to termination or 
voluntary separation.  External Entity will notify Valleywise Health within twenty-four (24) hours when an Authorized 
User’s role-based access to the Valleywise Health EHR System is no longer valid. External Entity further agrees to 
validate that the Authorized Users listed in Exhibit A continue to require access to the System and continue to be 
employees or agents of External Entity, thirty (30) days from the date of this Agreement and every thirty (30) days 
thereafter. Exhibit A and/or any revisions to Exhibit A should be sent to Valleywise Health via email to 
EHR.Access@valleywisehealth.org. 
 
2.5 
External Entity understands and warrants that EHR access and use shall be limited to that achieved through 
unique access codes provided to each individual Authorized User by Valleywise Health, and that each Authorized User 
shall be prohibited from using another authorized user’s access code to access and/or use the Valleywise Health EHR 
System. Authorized User’s use of another authorized user’s access code to access and/or use the Valleywise Health EHR 
System or provision of Authorized User’s access code to another person shall be considered a material breach of this 
Agreement. External Entity further acknowledges and understands that Valleywise Health retains absolute control over 
access to its EHR and that it may terminate individual Authorized Users’ access and/or the entire System License at any 
time for any reason without penalty, regardless of any effect such termination may have on External Entity’s operations. 
 
2.6 
External Entity at its own expense and at no cost to Valleywise Health, will provide and maintain the hardware, 
components, software, operating system(s), applications, network access, and interfaces necessary for External Entity to 
access and use the Valleywise Health EHR System.  External Entity is solely responsible for its own hardware, operating 
system(s), network applications and interfaces to permit External Entity’s connection with the Valleywise Health EHR 
System.  Valleywise Health shall not be responsible for the procurement, installation or maintenance of any necessary

3 
 
software, hardware and/or components, and Valleywise Health makes no representations or warranties regarding 
External Entity’s software, hardware and/or components whatsoever. 
 
3. Use or Disclosure of PHI. 
 
3.1 
External Entity shall not use or disclose any Protected Health Information (“PHI”) received from Valleywise 
Health in any manner that would constitute a violation of federal or state law, including, but not limited to, HIPAA.  
External Entity shall ensure that its directors, officers, employees, vendors, contractors, and agents use or disclose PHI 
received from, or created and/or received on behalf of Valleywise Health only in accordance with the provisions of this 
Agreement and federal and state law.  External Entity further agrees that all information accessed through this Agreement 
and through the Valleywise Health EHR System will be maintained in the strictest confidentiality and in the same manner 
as the External Entity safeguards the confidentiality of its protected health information, or as required by state and federal 
law. External Entity shall limit Authorized User access to only those persons or entities having a duly executed 
HIPAA/HITECH Business Associate Agreement.  
 
3.2 
External Entity Authorized User will not further disclose any PHI in violation of this agreement.  
 
4. External Entity Confidentiality Statement Requirement. 
 
4.1 
Before access to the Valleywise Health EHR System, each External Entity Authorized User shall read and agree 
to the terms of the confidentiality statement (the “Confidentiality Statement—Terms and Conditions of Use”) in the form 
provided herein as Exhibit B, attached hereto and incorporated herein by reference, as that form may be amended from 
time to time.  Before being granted access to the Valleywise Health EHR System, each Authorized User shall sign the 
Confidentiality Statement – Terms and Conditions of Use and provide the executed document to Valleywise Health.  
External Entity agrees to ensure that each Authorized User approved for access under this Agreement adheres to the 
requirements of this Agreement and the Confidentiality Statement – Terms and Conditions of Use. 
 
4.2 
External Entity shall provide Valleywise Health with a group e-mail address to which Valleywise Health may 
generate notices of records availability herein on Exhibit A. External Entity shall provide the e-mail address and direct 
phone number of each Authorized User noted herein on Exhibit A. Exhibit A and/or any revisions to Exhibit A should 
be sent to Valleywise Health via e-mail to EHR.Access@valleywisehealth.org. 
 
5. Safeguards Against Unauthorized Use or Disclosure of Information. 
 
5.1     External Entity agrees that it will implement all appropriate safeguards to prevent unauthorized use or disclosure 
of PHI belonging to Valleywise Health.  External Entity agrees to comply with all federal and state laws and regulations 
regarding privacy, security, and electronic exchange of health information, as currently enacted or amended in the future.  
External Entity agrees that it will not save or place Valleywise Health Confidential Information, including Valleywise 
Health patient’s PHI, to portable media devices including, but not limited to, “Thumb Drives”, Memory Sticks, DVDs, 
Floppies, CDs, PDAs, and other devices now known or hereinafter invented. 
 
5.2      For purposes of this Agreement the term “Valleywise Health Confidential Information” includes but is not limited 
to (i) all Valleywise Health technical, business and financial information including, without limitation, all information, 
licenses, business plans, data, structures, models, techniques, and processes, or (ii) in the case of information given 
verbally such information is disclosed in a manner such that a reasonable person would understand its confidential or 
proprietary nature, or (iii) where the disclosure of such confidential or proprietary information would cause demonstrable 
and material harm to Valleywise Health and would place Valleywise Health at a competitive disadvantage in the 
marketplace.

4 
 
6. Data Ownership. 
 
External Entity acknowledges and agrees that Valleywise Health owns all rights, interests and title in and to its data, 
including but not limited to PHI, and that such rights, interests and title shall remain vested in Valleywise Health at all 
times.  External Entity shall not compile and/or distribute analyses to third parties utilizing any data received from or 
created or received on behalf of Valleywise Health without express prior written permission from Valleywise Health. 
 
7. Reporting of Unauthorized Use or Disclosure of PHI. 
 
7.1 
External Entity shall, within twenty-four (24) hours of becoming aware or has reason to believe of an 
unauthorized use or disclosure of Valleywise Health’ PHI by External Entity, any of its Authorized Users, and its officers, 
directors, employees, vendors, contractors, agents or by a third party to which External Entity disclosed PHI, report any 
such disclosure to Valleywise Health.  Such notice shall be made to the following: 
 
Valleywise Health:   
Chief Compliance Officer 
 
   
Valleywise Health 
 
ADDRESS: 
2601 E. Roosevelt Street, <NEW ADDRESS> 
 
 
Phoenix, AZ 85008 
 
PHONE: 
(602)344-5915 
Copy To:  
Compliance Executive Assistant 
      
Valleywise Health 
 
ADDRESS: 
2619 E. Pierce Street, 1st Floor 
 
 
Phoenix, AZ 85008 
 
E-Mail: 
EHR.Access@valleysisehealth.org  
 
7.2 
Potential Data Security Breach. If at any time External Entity has reason to believe that PHI accessed, disclosed, 
or transmitted pursuant to this Agreement may have been accessed or disclosed without proper authorization and contrary 
to the terms of this Agreement, External Entity will immediately, but in no case more than twenty-four (24) hours, give 
Valleywise Health notice and take actions to eliminate the cause of the breach.  To the extent Valleywise Health deems 
warranted, in its sole discretion, Valleywise Health will provide notice or require External Entity, at its sole cost and 
expense, to provide notice to individuals whose PHI may have been improperly accessed or disclosed. 
 
7.3 
Valleywise Health has the right, at any time, to monitor, audit, and review External Entity’s activities and 
methods in implementing this Agreement in order to assure compliance therewith, within the limits of External Entity’s 
technical capabilities. 
 
8. Third Party Access. 
 
External Entity shall obtain the written approval from Valleywise Health prior to allowing any agent or subcontractor 
access to PHI that is created and/or received on behalf of Valleywise Health.  In the event that Valleywise Health consents 
to such third-party access on a case-by-case basis, External Entity shall ensure that the agent or subcontractor agrees to 
be bound by the same restrictions, terms and conditions that apply to External Entity through this Agreement.  External 
Entity shall require that any agent or subcontractor notify the External Entity of any instances in which PHI is used or 
disclosed in an unauthorized manner.  External Entity shall take steps to cure the breach of confidentiality and end the 
violation and/or terminate the agency agreement or subcontract. External Entity and any authorized agent or designee 
shall comply with Valleywise Health’ policies concerning access to PHI. Any entity presenting as a designee or

5 
 
authorized agent of External Entity shall furnish to Valleywise Health such evidence of agency or engagement by 
External Entity prior to any records being released to such entity, including a duly executed HIPAA/HITECH Business 
Associate Agreement. 
 
9. Maintenance and Availability of Books and Records. 
 
For a period of ten (10) years after the termination or expiration of this Agreement, External Entity agrees to maintain 
and make its internal practices, books and records relating to the use and disclosure of PHI received from Valleywise 
Health, or created or received on behalf of Valleywise Health, available to Valleywise Health and to the Secretary of the 
U.S. Department of Health and Human Services for purposes of determining Valleywise Health’ and External Entity’s 
compliance with the HIPAA standards.  External Entity promptly shall provide to Valleywise Health a copy of any 
documentation that External Entity provides to the Secretary. 
 
10. Investigations/Sanctions. 
 
Valleywise Health reserves the right to monitor, review and investigate any External Entity activity under this 
Agreement, including any reported and/or identified failures to comply with this Agreement and impose nonmonetary 
appropriate sanctions.  Sanctions may include, but are not limited to, the termination of this Agreement, termination of 
External Entity’s access, or termination of any individual Authorized User access.  External Entity agrees to cooperate 
with all Valleywise Health investigations into whether terms of this Agreement have been violated.  Failure to cooperate 
can be considered a material breach and result in automatic termination of Authorized User access.  Valleywise Health 
reserves the right to report unprofessional conduct to appropriate licensing or other regulatory authorities.  External 
Entity agrees to cooperate with Valleywise Health in order to adequately investigate complaints received involving the 
External Entity’s employees or agents.  External Entity agrees to have a sanctions policy, produce it upon request, and 
discipline their employees or agents for all breaches involving Valleywise Health PHI in accordance with the HIPAA 
Privacy and Security Rule(s).  External Entity understands that lack of adherence to this section allows Valleywise Health 
to immediately terminate this Agreement and all associated access privileges. 
 
11. Termination. 
 
11.1 
Immediate Termination.  Valleywise Health may terminate its participation in this Agreement immediately 
without liability for such termination, in the event Valleywise Health determines that External Entity, or External Entity’s 
Authorized User, directors, officers, employees, vendors, contractors or agents have violated a material provision of this 
Agreement.  
 
11.2 
Termination.  Either party may terminate this Agreement without cause, upon thirty (30) days prior written 
notice. 
 
12. Limitation of Liability; Indemnification. 
 
12.1 
Limitation of Liability. Except as provided in Section 12.3, neither Valleywise Health nor External Entity will 
be liable to the other for any special, incidental, exemplary, indirect, consequential or punitive damages (including loss 
of use or lost profits) the extent arising out of or in connection with claims relating to Valleywise Health’ or External 
Entity’s acts or omissions under this Agreement, including but not limited to claims, to the extent such claims arise from 
any delay, omission or error in the transmission of PHI, provision or receipt of PHI, or the handling or storage of PHI, 
or whether such liability arises from any claim based upon contract, warranty, tort (including negligence), product 
liability or otherwise, and whether or not either party has been advised of the possibility of such loss or damage. 
 
12.2 
Release of Liability.  Consistent with and notwithstanding any other provision in this Agreement to the contrary, 
External Entity releases Valleywise Health from any claims arising out of the inaccuracy or incompleteness of the PHI 
contained in the Valleywise Health EHR System except in cases arising out of Valleywise Health’ gross negligence.

6 
 
External Entity also releases Valleywise Health from any claims relating to the clinical, medical or other decisions related 
to the treatment of a patient, including those arising out of the unavailability of PHI through the Valleywise Health EHR 
System, except for those arising out of Valleywise Health’ gross negligence. 
 
12.3 
Mutual Indemnification. Each party (as “indemnitor”) agrees to indemnify, defend and hold harmless 
the other party (as “indemnitee”) from and against any and all claims, losses, liability, costs or expenses 
(including reasonable attorney’s fees) (hereinafter collectively referred to as “claims”) arising out of bodily 
injury of any person (including death) or property damage, but only to the extent that such claims, which result 
in vicarious/derivative liability to the indemnitee, are caused by the act, omission, negligence, misconduct, or 
other fault of the indemnitor, its officers, officials, agents, employees or volunteers. 
 
13. Insurance. 
 
External Entity shall maintain insurance coverage in amounts that will satisfy its indemnification obligation in this 
Agreement, including but not limited to comprehensive general liability insurance, professional liability insurance (in 
the minimum amount of $1,000,000 per claim and $3,000,000 in aggregate per year), errors and omission insurance, 
directors and officers insurance, and HIPAA and cyber-security breach insurance in the amount of $5,000,000 in 
aggregate per year.  External Entity shall provide Valleywise Health evidence of such insurance upon request. 
 
14. Privacy/HIPAA. 
 
Valleywise Health and External Entity shall comply in all material respects with the standards for privacy and security 
of protected health information of the Administrative Simplification subtitle of HIPAA and HITECH.  Valleywise Health 
and External Entity recognize their status as “covered entities” under HIPAA and agree to carry out their responsibilities 
under this Agreement in accordance with such status. 
 
15. Severability. 
 
Any provision of this Agreement which is determined to be invalid, void or illegal shall in no way affect, impair or 
invalidate any other provision hereof, and remaining provisions shall remain in full force and effect.  
 
16. Entire Agreement. 
 
This Agreement constitutes the entire agreement between the parties regarding access to Valleywise Health EHR System, 
and supersedes all prior oral or written agreements, commitments, or understandings concerning the matters provided 
for herein. 
 
17. Amendment. 
 
This Agreement may be modified only by a subsequent written Agreement executed by the parties.  The provisions in 
this Agreement may not be modified by any attachment, or letter agreement. 
 
18. Governing Law. 
 
This Agreement is governed by and interpreted in accordance with Arizona laws, without regard to its conflict of law 
provisions.  The Parties agree that jurisdiction over any action arising out of or relating to this Agreement shall be brought 
or filed in the federal or state courts located in Maricopa County, Arizona.

7 
 
19. Waiver. 
 
Neither the waiver by any of the parties hereto of a breach of, or a default under any of the provisions of this Agreement, 
nor the failure of either of the parties, on one or more occasions, to enforce any of the provisions of this Agreement or 
to exercise any right or privilege hereunder, will thereafter be construed as a waiver of any subsequent breach or default 
of a similar nature, or as a waiver of any of such provisions, rights or privileges hereunder. 
 
20. Term. 
 
This Agreement is effective as of the Effective Date listed above and will automatically renew after two (2) years from 
the Effective Date for a period of one (1) years unless otherwise terminated by either party as provided for in Section 
11. 
 
21. Survival.   
 
Unless expressly stated otherwise herein, the provisions and obligations contained in Paragraphs 5, 7, 8, 12, 13, 14, 18, 
and 19 shall survive the termination or expiration of this Agreement for a period of five (5) years after the date of 
expiration or termination. 
 
 
[SIGNATURE PAGE TO FOLLOW]

8 
 
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the date first above written. 
 
Valleywise Health  
 
By: ___________________________________   
 
Printed Name: ___________________________ 
 
Title: __________________________________  
 
Date: __________________________________ 
 
 
EXTERNAL ENTITY 
 
IN WITNESS WHEREOF, the parties agree to enter into this Agreement:  
FOR AND ON BEHALF OF MARICOPA COUNTY:  
 
 
 
__________________________________ 
 
 
Bill Gates, Chairman, Board of Supervisors 
_____________ 
 
 
Date 
 
 
ATTEST: 
 
 
 
 
 
 
 
 
__________________________________ 
 
 
Juanita Garza, Clerk of the Board 
 
_____________ 
 
 
Date 
 
 
APPROVED AS TO FORM: 
 
 
__________________________________ 
 
 
Anne Longo, Attorney for Maricopa County 
 
_____________ 
 
 
Date

9 
 
Exhibit A 
 
EXTERNAL ENTITY PRIVACY OFFICER CONTACT INFORMATION: 
 
NAME:           Joel Kodicek                                         
 
PHONE:         602-506-6606                                        
 
EMAIL:          Joel.Kodicek@maricopa.gov                
 
 
EXTERNAL ENTITY ADMINISTRATOR CONTACT INFORMATION: 
 
NAME: _______________________________________ 
 
PHONE: ______________________________________ 
 
EMAIL: _______________________________________ 
 
 
LIST OF EXTERNAL ENTITY’S 
AUTHORIZED USERS 
 
Below is a list of the names of the persons who are External Entity’s Authorized Users and who are therefore 
authorized to receive access to Valleywise Health PHI: 
 
 
Name  
 
 
 
        Role 
 
Phone  
 
E-Mail 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Designated External Entity group email address for Valleywise Health notices:  
 
_________________________________ 
 
Exhibit A and/or any revisions to Exhibit A should be sent to Valleywise Health via e-mail to 
EHR.Access@mihs.org.

10 
 
Exhibit B 
 
CONFIDENTIALITY STATEMENT 
 
Terms & Conditions of Use 
 
The protection of health and other confidential information, including but not limited to PHI, is a right protected 
by law and enforced by fines, criminal penalties as well as policy.  Safeguarding protected health information 
(“PHI”) is a fundamental obligation for all persons accessing it.  Your signature at the end of this statement will 
commit you to that obligation and WILL be used as proof that you understand and agree to the stated basic duties 
and facts regarding privacy. 
 
Read it carefully. 
 
Signing below indicates the following: 
 
1.  I agree to protect the privacy and security of confidential or protected health information I access through Valleywise 
Health’ electronic health records (“EHR”) at all times. 
 
2.  I agree to 
a) access EHR and/or PHI only to the minimum extent necessary for my assigned duties and 
 
b) disclose such information only to persons authorized to receive it. 
 
3.  I understand and agree that: 
 
a.  Valleywise Health tracks all user IDs used to access electronic records.  Those IDs enable discovery of 
inappropriate access to patient records. 
 
b.  Inappropriate access and/or unauthorized release of confidential or PHI will result in disciplinary action, up to 
and including termination of employment, and will result in a report to authorities charged with professional 
licensing, enforcement of privacy laws and prosecution of criminal acts.  I further understand and agree that 
inappropriate access and/or unauthorized release of confidential or protected information may result in temporary 
and/or permanent termination of my access to Valleywise Health electronic records. 
 
c.  I will be assigned a User ID and a one-time use activation code.  I agree to immediately select and enter a new 
password known only to me.  I understand I may change my password at any time and will do so based on Valleywise 
Health established policy and/or when prompted.  I understand that I am to be the only individual using and in 
possession of my confidential password.  I am aware that the User ID and password are equivalent to my signature.  
Also, I am aware that I am responsible for any use of the system utilizing my User ID and password.  This includes 
data entered, viewed, printed or otherwise manipulated.  If I have reason to believe that my password has been 
compromised, I will report this information to Valleywise Health, and I will also immediately change my password.  
I understand that User IDs cannot be shared.  Inappropriate use of my ID (whether by me or anyone else) is my 
responsibility and exposes me to severe consequences. 
 
4.  I understand that PHI includes but is not limited to: 
 
Any individually identifiable information in possession or derived from a provider of health care regarding a patient's 
medical history, mental, or physical condition or treatment, as well as the patients and/or their family members 
records, test results, conversations, research records and financial information.  (Note: this information is defined in 
the Privacy Rule as “protected health information.”).  Examples include, but are not limited to:

11 
 
  
-Physical medical and psychiatric records including paper, photo, video, diagnostic and therapeutic reports, 
laboratory and pathology samples;  
-Patient insurance and billing records;  
-Centralized and/or department based computerized patient data (including any form of electronic storage 
media). 
  
External Entity Authorized User: 
 
Signature:  _____________________________________ 
 
Printed Name: __________________________________ 
 
Title:                                                                                     
 
Email:  ________________________________________   
 
Date:                              
 
DOB:                             
 
Location Address:                                                                                      
 
                                                                                                                    
 
                                                                                                                    
 
Work Phone: ____________________________________________________